KHRAT

First seen
2018-06-20 00:00:00
Malware type
rat, keylogger, screen-capture, trojan
Family
Malware family
Profile updated
2026-07-07 12:48:17

Targeted industries: government-and-public-sector

Targeted regions: country_code:kh

Context

According to Unit42, KHRAT is a Trojan that registers victims using their infected machine’s username, system language and local IP address. KHRAT provides the threat actors typical RAT features and access to the victim system, including keylogging, screenshot capabilities, remote shell access and so on.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Khrat_Auto (yara-rule)

Reports & references

  • forcepoint.com — Trojanized Adobe Installer Used Install Dragonok S New Custom Backdoor (report)
  • Palo Alto Unit 42 — Rancortaurus (report)
  • Palo Alto Unit 42 — Rancor Cyber Espionage Group Uses New Custom Malware To Attack Southeast Asia (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Khrat (report)
  • researchcenter.paloaltonetworks.com — Unit42 Updated Khrat Malware Used In Cambodia Attacks (report)

External references